Privacy Policy
Version 1.1 · Effective 1 September 2026
1. Who we are
1.1 Wayforward Programs LLC is the data controller for swim.institute and platform.swim.institute. Questions and requests go to contact@swim.institute.
1.2 The SWIM Institute is an independent certifying body and receives only what section 5 describes.
2. What we collect
2.1 When you apply, we collect your name, email address, telephone number, postal address, employer, job title, LinkedIn profile, your resume, your answers to the background and open-text questions, and the cohort you asked for.
2.2 When you create an account, we hold a password you set, which we never see in readable form, your time zone, and your acceptance of the Platform Terms of Use recorded with your typed name and the date.
2.3 When you pay, Stripe handles the payment and we never receive or store your card number. We keep the amount, the date, the method type, the payer name and email, and Stripe's own references.
2.4 While you train, we hold your coursework submissions, assessment results, session bookings and attendance, and any merchandise orders you place.
3. Why we hold it
3.1 To decide your application, to run your enrollment and coursework, to take payment and issue receipts, to award and maintain your credential, and to meet our record-keeping obligations.
4. IP addresses
4.1 The application form and the credential verification page each count requests to prevent abuse. Both store a one-way hash of the requesting address rather than the address itself, and the hashes are pruned on a rolling basis. We do not use them to identify anyone.
5. Who else sees your information
5.1 We do not sell your information. Section 10 describes the measurement services that run on our sites and what they receive.
5.2 Lovable hosts swim.institute and platform.swim.institute and processes the traffic between you and those applications.
5.3 Supabase is our database, authentication, and file storage provider, and holds everything described above.
5.4 Stripe processes payments and holds the payment details you enter directly with them.
5.5 Resend delivers our email and receives your email address and the content of the message.
5.6 Accredible is our credentialing platform, and receives your name, your email address, the name of your credential, and the dates your credential was issued and expires.
5.7 Printful fulfills merchandise orders and receives the name and shipping address for that order.
5.8 The SWIM Institute, an independent certifying body, receives your name, your professional history, and the dates you met each course requirement.
5.9 Microsoft, through its Clarity service, receives the website usage information described in section 10.
5.10 LinkedIn receives the website usage information described in section 10.
6. How we protect it
6.1 Card details never reach us. Payment happens on Stripe's own hosted page, and we receive only an amount, a date, a method type, and Stripe's references. Card data is never transmitted to or stored on our systems.
6.2 Traffic between you and our applications is encrypted in transit.
6.3 Every table in our database carries row-level access control, so a request only returns the rows the requester is entitled to see.
6.4 Files, including your resume and any coursework you upload, are held in private storage. They are reachable only through a short-lived signed link issued after a permission check on the server, and never through a public address.
6.5 Passwords are held by our authentication provider in hashed form. They are not stored in our own tables and no member of staff can view them.
6.6 Source addresses used for rate limiting are stored as a one-way hash rather than the address itself.
6.7 Assessment material and the scoring that applies to it stay on the server and are never sent to the browser.
6.8 Privileged actions are written to an audit trail recording who acted, what changed, and why.
6.9 Requests to the application form and the credential verification page are rate limited.
6.10 If we become aware of a breach affecting your information, we will notify you and the relevant authorities as the law requires, without undue delay.
6.11 No system is perfectly secure. These measures reduce risk, and they do not eliminate it.
7. The public register
7.1 Anyone can look up a credential at swim.institute/verify without an account. A successful search returns the holder's name, the credential, the date it was issued, the date its term ends, whether it is active, expired, or revoked, and a link to the credential record.
7.2 You may ask us to remove your name from search, in which case your credential remains verifiable by its identifier but will not be found by name. Write to contact@swim.institute.
8. How long we keep it
8.1 Application records and credential records are kept as part of the permanent record of the certification, because a credential has to remain verifiable long after it is awarded.
8.2 Payment records are kept as long as our financial and tax obligations require. Other operational records are kept only as long as they are useful for the purpose they were collected for.
9. Your choices
9.1 You may ask for a copy of what we hold, ask us to correct it, ask us to remove your name from the public register, or ask us to delete what we are not required to keep. Write to contact@swim.institute.
9.2 Some records cannot be deleted while a credential stands, since deleting them would make the credential unverifiable.
10. Website measurement
10.1 swim.institute uses Microsoft Clarity to show us how the site is used. Clarity records the pages you view, where you click, how far you scroll, your mouse movement, your browser and device type, and an approximate location derived from your IP address. It assembles these into an anonymized playback of the visit and into aggregate maps of clicks and scrolling.
10.2 Clarity is set to mask text. Anything you type is replaced before it leaves your browser, so Clarity never receives it.
10.3 The application form is served from platform.swim.institute inside a frame, and Clarity does not capture anything inside that frame.
10.4 swim.institute also carries the LinkedIn Insight Tag, which reports to LinkedIn that a visit occurred and that an application was started or submitted. It reports the page address, your IP address, your browser and device type, and LinkedIn's own cookie if you have one. It does not report the contents of your application.
10.5 Both services set cookies. You can block them with browser settings or an ad blocker, and the site works normally when you do. LinkedIn members can opt out at linkedin.com/psettings/guest-controls/retargeting-opt-out.
10.6 The LinkedIn Insight Tag is also present on platform.swim.institute, where the application form is served, and it reports the same information described in 10.4 on pages you view there, including pages you view while signed in. platform.swim.institute does not carry Clarity.
11. Changes and governing law
11.1 We will post any revision on this page with a new version number and effective date, and material changes will be sent to candidates by email.
11.2 This policy is governed by the laws of the State of New York.
This policy describes current practice. If something here does not match what you experience, write to contact@swim.institute and we will look into it.